Executive Summary

Informations
Name CVE-2023-33176 First vendor Publication 2023-06-26
Vendor Cve Last vendor Modification 2023-07-05

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Overall CVSS Score 6.5
Base Score 6.5 Environmental Score 6.5
impact SubScore 2.5 Temporal Score 6.5
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Unchanged Confidentiality Impact Low
Integrity Impact Low Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

BigBlueButton is an open source virtual classroom designed to help teachers teach and learners learn. In affected versions are affected by a Server-Side Request Forgery (SSRF) vulnerability. In an `insertDocument` API request the user is able to supply a URL from which the presentation should be downloaded. This URL was being used without having been successfully validated first. An update to the `followRedirect` method in the `PresentationUrlDownloadService` has been made to validate all URLs to be used for presentation download. Two new properties `presentationDownloadSupportedProtocols` and `presentationDownloadBlockedHosts` have also been added to `bigbluebutton.properties` to allow administrators to define what protocols a URL must use and to explicitly define hosts that a presentation cannot be downloaded from. All URLs passed to `insertDocument` must conform to the requirements of the two previously mentioned properties. Additionally, these URLs must resolve to valid addresses, and these addresses must not be local or loopback addresses. There are no workarounds. Users are advised to upgrade to a patched version of BigBlueButton.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-33176

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 33

Sources (Detail)

Source Url
MISC https://github.com/bigbluebutton/bigbluebutton/commit/43394dade595d0707384e48...
https://github.com/bigbluebutton/bigbluebutton/commit/b18aff32e65a47f1eb2c800...
https://github.com/bigbluebutton/bigbluebutton/pull/18045
https://github.com/bigbluebutton/bigbluebutton/pull/18052
https://github.com/bigbluebutton/bigbluebutton/security/advisories/GHSA-3q22-...

Alert History

If you want to see full details history, please login or register.
0
1
2
3
Date Informations
2023-11-08 13:34:40
  • Multiple Updates
2023-07-05 21:27:21
  • Multiple Updates
2023-06-27 05:27:20
  • Multiple Updates
2023-06-27 00:27:18
  • First insertion